URL:

https://bestploits.com/main/synapse-x-crack/

Full analysis: https://app.any.run/tasks/e1b93b15-7746-4f34-b3b1-91adfe16f005
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: February 13, 2021, 00:30:11
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
adware
pua
lavasoft
loader
Indicators:
MD5:

59C7569C894616B65A9795983C022E3B

SHA1:

5FCCB36EA23E4E86E89096E8A340973F11CFE285

SHA256:

F98DB6EB75CF28886D951935A0F816BF479951BC3BD7C18523AF97FCDA16A85C

SSDEEP:

3:N8vVJOKKI/8vIZK:2bZ6IZK

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • installer.exe (PID: 3260)
      • GenericSetup.exe (PID: 272)
      • WebCompanionInstaller.exe (PID: 1248)
      • SystemAssistant.exe (PID: 3404)
      • SANotifications.exe (PID: 3168)
      • WebCompanion.exe (PID: 2520)
      • Lavasoft.WCAssistant.WinService.exe (PID: 2964)
      • WebCompanion.exe (PID: 3888)
    • Drops executable file immediately after starts

      • SYNAPSE X.exe (PID: 3800)
      • 10kc1st5.pun.exe (PID: 2624)
      • SystemAssistant@mkey4-water.exe (PID: 2088)
    • Application was dropped or rewritten from another process

      • SYNAPSE X.exe (PID: 3800)
      • installer.exe (PID: 3260)
      • GenericSetup.exe (PID: 272)
      • SYNAPSE X.exe (PID: 972)
      • WebCompanionInstaller.exe (PID: 1248)
      • SystemAssistant@mkey4-water.exe (PID: 2088)
      • 10kc1st5.pun.exe (PID: 2624)
      • SANotifications.exe (PID: 3168)
      • SystemAssistant.exe (PID: 3404)
      • WebCompanion.exe (PID: 2520)
      • FileExtr.actor-setup.exe (PID: 120)
      • Lavasoft.WCAssistant.WinService.exe (PID: 2964)
      • Ad-Aware Web Companion.exe (PID: 1740)
      • FM.exe (PID: 2468)
      • WebCompanion.exe (PID: 3888)
      • FileExtr.actor-setup.exe (PID: 3912)
      • FileExtr.actor-setup.exe (PID: 3980)
    • LAVASOFT was detected

      • installer.exe (PID: 3260)
    • Changes settings of System certificates

      • GenericSetup.exe (PID: 272)
      • WebCompanionInstaller.exe (PID: 1248)
      • SystemAssistant.exe (PID: 3404)
    • Actions looks like stealing of personal data

      • SANotifications.exe (PID: 3168)
      • SystemAssistant.exe (PID: 3404)
      • WebCompanion.exe (PID: 2520)
    • Steals credentials from Web Browsers

      • SANotifications.exe (PID: 3168)
      • SystemAssistant.exe (PID: 3404)
      • WebCompanion.exe (PID: 2520)
    • Uses Task Scheduler to autorun other applications

      • SystemAssistant.exe (PID: 3404)
    • Loads the Task Scheduler COM API

      • schtasks.exe (PID: 3416)
    • Changes internet zones settings

      • WebCompanionInstaller.exe (PID: 1248)
    • Changes the autorun value in the registry

      • WebCompanion.exe (PID: 2520)
    • Starts Visual C# compiler

      • WebCompanion.exe (PID: 2520)
      • Lavasoft.WCAssistant.WinService.exe (PID: 2964)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • firefox.exe (PID: 3904)
      • SYNAPSE X.exe (PID: 3800)
      • GenericSetup.exe (PID: 272)
      • 10kc1st5.pun.exe (PID: 2624)
      • SystemAssistant@mkey4-water.exe (PID: 2088)
      • SystemAssistant@mkey4-water.tmp (PID: 3460)
      • WebCompanionInstaller.exe (PID: 1248)
      • FileExtr.actor-setup.exe (PID: 120)
      • FileExtr.actor-setup.tmp (PID: 2852)
      • FileExtr.actor-setup.exe (PID: 3980)
      • FileExtr.actor-setup.exe (PID: 3912)
    • Drops a file with too old compile date

      • SYNAPSE X.exe (PID: 3800)
    • Drops a file that was compiled in debug mode

      • SYNAPSE X.exe (PID: 3800)
      • 10kc1st5.pun.exe (PID: 2624)
      • SystemAssistant@mkey4-water.tmp (PID: 3460)
      • WebCompanionInstaller.exe (PID: 1248)
    • Drops a file with a compile date too recent

      • SYNAPSE X.exe (PID: 3800)
      • 10kc1st5.pun.exe (PID: 2624)
      • GenericSetup.exe (PID: 272)
      • WebCompanionInstaller.exe (PID: 1248)
    • Reads Environment values

      • GenericSetup.exe (PID: 272)
    • Reads the Windows organization settings

      • GenericSetup.exe (PID: 272)
      • SystemAssistant@mkey4-water.tmp (PID: 3460)
      • FileExtr.actor-setup.tmp (PID: 2852)
    • Starts CMD.EXE for commands execution

      • GenericSetup.exe (PID: 272)
      • WebCompanionInstaller.exe (PID: 1248)
      • Lavasoft.WCAssistant.WinService.exe (PID: 2964)
    • Reads Windows owner or organization settings

      • GenericSetup.exe (PID: 272)
      • SystemAssistant@mkey4-water.tmp (PID: 3460)
      • FileExtr.actor-setup.tmp (PID: 2852)
    • Adds / modifies Windows certificates

      • GenericSetup.exe (PID: 272)
      • WebCompanionInstaller.exe (PID: 1248)
      • SystemAssistant.exe (PID: 3404)
    • Creates files in the program directory

      • WebCompanionInstaller.exe (PID: 1248)
      • SystemAssistant.exe (PID: 3404)
      • WebCompanion.exe (PID: 2520)
      • Lavasoft.WCAssistant.WinService.exe (PID: 2964)
      • WebCompanion.exe (PID: 3888)
    • Creates a directory in Program Files

      • SystemAssistant@mkey4-water.tmp (PID: 3460)
      • WebCompanionInstaller.exe (PID: 1248)
      • FileExtr.actor-setup.tmp (PID: 2852)
    • Reads CPU info

      • SystemAssistant.exe (PID: 3404)
    • Creates files in the user directory

      • SystemAssistant.exe (PID: 3404)
      • WebCompanionInstaller.exe (PID: 1248)
      • SANotifications.exe (PID: 3168)
      • WebCompanion.exe (PID: 2520)
    • Reads internet explorer settings

      • SystemAssistant.exe (PID: 3404)
    • Creates a software uninstall entry

      • WebCompanionInstaller.exe (PID: 1248)
    • Starts SC.EXE for service management

      • WebCompanionInstaller.exe (PID: 1248)
    • Searches for installed software

      • SANotifications.exe (PID: 3168)
      • FileExtr.actor-setup.tmp (PID: 2540)
      • GenericSetup.exe (PID: 272)
    • Reads the cookies of Mozilla Firefox

      • SystemAssistant.exe (PID: 3404)
    • Reads the cookies of Google Chrome

      • SystemAssistant.exe (PID: 3404)
    • Uses NETSH.EXE for network configuration

      • cmd.exe (PID: 2936)
      • cmd.exe (PID: 2804)
    • Executed as Windows Service

      • Lavasoft.WCAssistant.WinService.exe (PID: 2964)
      • PresentationFontCache.exe (PID: 1508)
    • Reads Microsoft Outlook installation path

      • SystemAssistant.exe (PID: 3404)
    • Creates files in the Windows directory

      • Lavasoft.WCAssistant.WinService.exe (PID: 2964)
      • csc.exe (PID: 3740)
      • WebCompanion.exe (PID: 2520)
      • WebCompanionInstaller.exe (PID: 1248)
    • Removes files from Windows directory

      • Lavasoft.WCAssistant.WinService.exe (PID: 2964)
      • csc.exe (PID: 3740)
      • WebCompanionInstaller.exe (PID: 1248)
    • Changes the started page of IE

      • WebCompanion.exe (PID: 2520)
  • INFO

    • Application launched itself

      • firefox.exe (PID: 3904)
      • firefox.exe (PID: 2156)
    • Reads CPU info

      • firefox.exe (PID: 3904)
    • Creates files in the user directory

      • firefox.exe (PID: 3904)
    • Reads settings of System Certificates

      • firefox.exe (PID: 3904)
      • GenericSetup.exe (PID: 272)
      • WebCompanionInstaller.exe (PID: 1248)
    • Creates files in the program directory

      • firefox.exe (PID: 3904)
      • SystemAssistant@mkey4-water.tmp (PID: 3460)
      • FileExtr.actor-setup.tmp (PID: 2852)
    • Creates a software uninstall entry

      • SystemAssistant@mkey4-water.tmp (PID: 3460)
      • FileExtr.actor-setup.tmp (PID: 2852)
    • Application was dropped or rewritten from another process

      • SystemAssistant@mkey4-water.tmp (PID: 3460)
      • FileExtr.actor-setup.tmp (PID: 2852)
      • FileExtr.actor-setup.tmp (PID: 336)
      • FileExtr.actor-setup.tmp (PID: 2540)
    • Dropped object may contain Bitcoin addresses

      • WebCompanionInstaller.exe (PID: 1248)
    • Manual execution by user

      • explorer.exe (PID: 2256)
      • FileExtr.actor-setup.exe (PID: 3980)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
99
Monitored processes
45
Malicious processes
20
Suspicious processes
4

Behavior graph

Click at the process to see the details
start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe firefox.exe firefox.exe synapse x.exe no specs synapse x.exe #LAVASOFT installer.exe genericsetup.exe cmd.exe no specs 10kc1st5.pun.exe webcompanioninstaller.exe cmd.exe no specs systemassistant@mkey4-water.exe systemassistant@mkey4-water.tmp sanotifications.exe systemassistant.exe schtasks.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs cmd.exe no specs netsh.exe no specs webcompanion.exe cmd.exe no specs fileextr.actor-setup.exe fileextr.actor-setup.tmp lavasoft.wcassistant.winservice.exe csc.exe no specs cmd.exe no specs netsh.exe no specs cvtres.exe no specs firefox.exe no specs csc.exe cvtres.exe no specs ad-aware web companion.exe no specs fm.exe no specs webcompanion.exe explorer.exe no specs presentationfontcache.exe no specs fileextr.actor-setup.exe fileextr.actor-setup.tmp no specs fileextr.actor-setup.exe fileextr.actor-setup.tmp no specs

Process information

PID
CMD
Path
Indicators
Parent process
120"C:\Users\admin\Downloads\FileExtr.actor-setup.exe"C:\Users\admin\Downloads\FileExtr.actor-setup.exe
cmd.exe
User:
admin
Company:
FileExtr.actor
Integrity Level:
HIGH
Description:
FileExtr.actor Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\downloads\fileextr.actor-setup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
128"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3904.20.689683835\797991032" -childID 3 -isForBrowser -prefsHandle 3700 -prefMapHandle 3704 -prefsLen 6718 -prefMapSize 191824 -parentBuildID 20190717172542 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 3904 "\\.\pipe\gecko-crash-server-pipe.3904" 3716 tabC:\Program Files\Mozilla Firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
68.0.1
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
272"C:\Users\admin\AppData\Local\Temp\7zS8DE3209D\GenericSetup.exe" C:\Users\admin\AppData\Local\Temp\7zS8DE3209D\GenericSetup.exe hik=4f2e4324-6c8e-4707-bd0d-243712422087 hmk=0a212413-37ac-8b3b-b257-988ffe3e958d hut=Admin hpp="QzpcVXNlcnNcYWRtaW5cRG93bmxvYWRzXFNZTkFQU0UgWC5leGU=" hts=1613176279948C:\Users\admin\AppData\Local\Temp\7zS8DE3209D\GenericSetup.exe
installer.exe
User:
admin
Integrity Level:
HIGH
Description:
Software Installation
Exit code:
0
Version:
1.3.1.3934
Modules
Images
c:\users\admin\appdata\local\temp\7zs8de3209d\genericsetup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
336"C:\Users\admin\AppData\Local\Temp\is-AJJD2.tmp\FileExtr.actor-setup.tmp" /SL5="$50142,8504940,1086976,C:\Users\admin\Downloads\FileExtr.actor-setup.exe" C:\Users\admin\AppData\Local\Temp\is-AJJD2.tmp\FileExtr.actor-setup.tmpFileExtr.actor-setup.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-ajjd2.tmp\fileextr.actor-setup.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
468"C:\Windows\system32\cmd.exe" /C ""SystemAssistant@mkey4-water.exe" /verysilent"C:\Windows\system32\cmd.exeGenericSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
748"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3904.13.1482353997\954021796" -childID 2 -isForBrowser -prefsHandle 3000 -prefMapHandle 3004 -prefsLen 5996 -prefMapSize 191824 -parentBuildID 20190717172542 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 3904 "\\.\pipe\gecko-crash-server-pipe.3904" 2996 tabC:\Program Files\Mozilla Firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
68.0.1
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
972"C:\Users\admin\Downloads\SYNAPSE X.exe" C:\Users\admin\Downloads\SYNAPSE X.exefirefox.exe
User:
admin
Company:
IC001
Integrity Level:
MEDIUM
Description:
Software Installation
Exit code:
3221226540
Version:
1.3.1.4130
Modules
Images
c:\users\admin\downloads\synapse x.exe
c:\systemroot\system32\ntdll.dll
1236netsh http add urlacl url=http://+:9007/ user=EveryoneC:\Windows\system32\netsh.execmd.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Network Command Shell
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\netsh.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\credui.dll
c:\windows\system32\user32.dll
1248.\WebCompanionInstaller.exe --partner=IT200301 --version=7.0.2388.4219 --prod --silent --homepage=1 --search=1 --partner=IT200301C:\Users\admin\AppData\Local\Temp\7zS04A5F62E\WebCompanionInstaller.exe
10kc1st5.pun.exe
User:
admin
Company:
Lavasoft
Integrity Level:
HIGH
Description:
Web Companion
Exit code:
0
Version:
7.0.2388.4219
Modules
Images
c:\users\admin\appdata\local\temp\7zs04a5f62e\webcompanioninstaller.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1508C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exeC:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exeservices.exe
User:
LOCAL SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
PresentationFontCache.exe
Exit code:
0
Version:
3.0.6920.4902 built by: NetFXw7
Modules
Images
c:\windows\microsoft.net\framework\v3.0\wpf\presentationfontcache.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
54 964
Read events
54 476
Write events
475
Delete events
13

Modification events

(PID) Process:(2156) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Launcher
Value:
3C1F960900000000
(PID) Process:(3904) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Browser
Value:
3C1F960900000000
(PID) Process:(3904) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry
Value:
1
(PID) Process:(3904) firefox.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(3904) firefox.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
46000000A5000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
(PID) Process:(3904) firefox.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3904) firefox.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(3904) firefox.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(272) GenericSetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(272) GenericSetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
Executable files
129
Suspicious files
136
Text files
490
Unknown types
91

Dropped files

PID
Process
Filename
Type
3904firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\scriptCache-current.bin
MD5:
SHA256:
3904firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite-shm
MD5:
SHA256:
3904firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs-1.js
MD5:
SHA256:
3904firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json.tmp
MD5:
SHA256:
3904firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shm
MD5:
SHA256:
3904firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\search.json.mozlz4.tmp
MD5:
SHA256:
3904firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\allow-flashallow-digest256.pset
MD5:
SHA256:
3904firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\allow-flashallow-digest256.sbstore
MD5:
SHA256:
3904firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\base-track-digest256.pset
MD5:
SHA256:
3904firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\base-track-digest256.sbstore
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
87
TCP/UDP connections
89
DNS requests
143
Threats
19

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3904
firefox.exe
GET
302
69.61.56.76:80
http://buba99.club/voluum/?a=&a_aid=5ebff5ee5b9fd&fn=U1lOQVBTRSBY&token=NDUuODYuMjAyLjE3&clientid=724578141
US
suspicious
3904
firefox.exe
GET
302
69.61.56.76:80
http://buba99.club/voluum/redirect.php?aff=5ebff5ee5b9fd&subaff=&exename=U1lOQVBTRSBY&title=Software%20Installer&description=Software%20Installer%20Player&tid=&type=&token=NDUuODYuMjAyLjE3&thankyou=&cinstaller=1&a=&token=NDUuODYuMjAyLjE3&clientid=724578141
US
suspicious
3904
firefox.exe
POST
200
93.184.220.29:80
http://ocsp.digicert.com/
US
der
471 b
whitelisted
3904
firefox.exe
POST
200
142.250.185.67:80
http://ocsp.pki.goog/gts1o1core
US
der
472 b
whitelisted
3904
firefox.exe
POST
200
142.250.185.67:80
http://ocsp.pki.goog/gts1o1core
US
der
472 b
whitelisted
3904
firefox.exe
POST
200
142.250.185.67:80
http://ocsp.pki.goog/gts1o1core
US
der
472 b
whitelisted
3904
firefox.exe
POST
200
142.250.185.67:80
http://ocsp.pki.goog/gts1o1core
US
der
472 b
whitelisted
3904
firefox.exe
POST
200
23.55.163.58:80
http://r3.o.lencr.org/
US
der
503 b
shared
3904
firefox.exe
POST
200
142.250.185.67:80
http://ocsp.pki.goog/gts1o1core
US
der
471 b
whitelisted
3904
firefox.exe
POST
200
93.184.220.29:80
http://ocsp.digicert.com/
US
der
471 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3904
firefox.exe
34.107.221.82:80
detectportal.firefox.com
US
whitelisted
3904
firefox.exe
87.236.16.124:443
bestploits.com
Beget Ltd
RU
suspicious
3904
firefox.exe
34.213.158.239:443
search.services.mozilla.com
Amazon.com, Inc.
US
unknown
3904
firefox.exe
23.55.163.58:80
r3.o.lencr.org
Akamai International B.V.
US
unknown
3904
firefox.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
3904
firefox.exe
13.225.80.38:443
content-signature-2.cdn.mozilla.net
US
unknown
3904
firefox.exe
2.16.186.10:80
r3.o.lencr.org
Akamai International B.V.
whitelisted
3904
firefox.exe
69.61.56.73:80
downloadxd.club
Cyber Wurx LLC
US
suspicious
3904
firefox.exe
69.61.56.76:80
buba99.club
Cyber Wurx LLC
US
suspicious
3904
firefox.exe
192.0.78.27:443
href.li
Automattic, Inc
US
suspicious

DNS requests

Domain
IP
Reputation
detectportal.firefox.com
  • 34.107.221.82
whitelisted
bestploits.com
  • 87.236.16.124
malicious
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
whitelisted
search.services.mozilla.com
  • 34.213.158.239
  • 35.165.106.166
  • 52.38.202.57
whitelisted
search.r53-2.services.mozilla.com
  • 52.38.202.57
  • 35.165.106.166
  • 34.213.158.239
whitelisted
push.services.mozilla.com
  • 44.237.239.70
whitelisted
autopush.prod.mozaws.net
  • 44.237.239.70
whitelisted
r3.o.lencr.org
  • 23.55.163.58
  • 23.55.163.48
  • 2.16.186.10
  • 2.16.186.11
shared
a1887.dscq.akamai.net
  • 23.55.163.48
  • 23.55.163.58
  • 2.16.186.11
  • 2.16.186.10
whitelisted
tiles.services.mozilla.com
whitelisted

Threats

PID
Process
Class
Message
1048
svchost.exe
Potentially Bad Traffic
ET INFO Observed DNS Query to .cloud TLD
1048
svchost.exe
Potentially Bad Traffic
ET INFO Observed DNS Query to .cloud TLD
3260
installer.exe
A Network Trojan was detected
ET MALWARE Lavasoft PUA/Adware Client Install
272
GenericSetup.exe
A Network Trojan was detected
ET INFO Suspicious Windows NT version 9 User-Agent
272
GenericSetup.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
272
GenericSetup.exe
Potential Corporate Privacy Violation
AV POLICY HTTP request for .exe file with no User-Agent
272
GenericSetup.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
272
GenericSetup.exe
Potentially Bad Traffic
ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download
272
GenericSetup.exe
Potential Corporate Privacy Violation
AV POLICY HTTP request for .exe file with no User-Agent
272
GenericSetup.exe
Potential Corporate Privacy Violation
AV POLICY HTTP request for .exe file with no User-Agent
1 ETPRO signatures available at the full report
Process
Message
installer.exe
[debug][2021-02-13 00:31:16.729265][installer][wWinMain][223]: bundle config file path=C:\Users\admin\AppData\Local\Temp\7zS8DE3209D\BundleConfig.json
installer.exe
[debug][2021-02-13 00:31:16.729265][installer][CreateBundleConfig][96]: DisableStubEvents=0
installer.exe
[debug][2021-02-13 00:31:16.729265][installer][wWinMain][230]: install id=4f2e4324-6c8e-4707-bd0d-243712422087
installer.exe
[debug][2021-02-13 00:31:19.916765][installer][wWinMain][234]: machine Id id=0a212413-37ac-8b3b-b257-988ffe3e958d
installer.exe
[debug][2021-02-13 00:31:19.948015][installer][wWinMain][386]: generic setup path=C:\Users\admin\AppData\Local\Temp\7zS8DE3209D\GenericSetup.exe
installer.exe
[debug][2021-02-13 00:31:19.948015][installer][EventService::SendEvent][29]: send event. event name=StubStart. disable stub events=0
installer.exe
[debug][2021-02-13 00:31:19.948015][installer][EventService::SendEvent][77]: StubStart data = {"Data":{"EventCategory":"Success","BundleId":"IC001","DeltaMs":0,"MachineId":"0a212413-37ac-8b3b-b257-988ffe3e958d","InstallId":"4f2e4324-6c8e-4707-bd0d-243712422087","PartnerVersion":"1.3.1.3934","BundleVersion":"6.0.2.0","OsVersion":"Microsoft Windows 7 Professional Service Pack 1 (build 7601), 32-bit","DotNetFramework":"3.5, 4.0 Client, 4.0 Full, 4.5, 4.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2, 4.7.0, 4.7.1, 4.7.2"}}
installer.exe
[debug][2021-02-13 00:31:19.948015][installer][ProcessService::GetProcessName][46]: Module filename is: C:\Users\admin\Downloads\SYNAPSE X.exe
installer.exe
[debug][2021-02-13 00:31:19.963640][installer][EventService::SendEvent][86]: url=http://flow.lavasoft.com/v1/event-stat?ProductID=IS&Type=StubStart
installer.exe
[debug][2021-02-13 00:31:19.963640][installer][wWinMain][393]: cmd=C:\Users\admin\AppData\Local\Temp\7zS8DE3209D\GenericSetup.exe hik=4f2e4324-6c8e-4707-bd0d-243712422087 hmk=0a212413-37ac-8b3b-b257-988ffe3e958d hut=Admin hpp="QzpcVXNlcnNcYWRtaW5cRG93bmxvYWRzXFNZTkFQU0UgWC5leGU=" hts=1613176279948